RULE(RULE ID:323032)

Rule General Information
Release Date: 2019-09-02
Rule Name: Apache httpd mod_remoteip Buffer Overflow Vulnerability (CVE-2019-10097)
Severity:
CVE ID:
Rule Protection Details
Description: There is a security vulnerability in Apache httpd. A remote attacker exploited the vulnerability by sending a specially crafted PROXY header to cause a denial of service. The following products and versions are affected: Apache httpd 2.4.38, 2.4.37, 2.4.35, 2.4.34, 2.4.33.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Others
Reference: https://www.debian.org/security/2019/dsa-4509
https://www.auscert.org.au/bulletins/ESB-2019.3301/
https://packetstormsecurity.com/files/154258/Ubuntu-Security-Notice-USN-4113-1.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://httpd.apache.org/security/vulnerabilities_24.html